rename environment variable to PLUTO_XAUTH_ID
This commit is contained in:
@@ -115,7 +115,7 @@
|
|||||||
# is the UDP/TCP port to which the IPsec SA is
|
# is the UDP/TCP port to which the IPsec SA is
|
||||||
# restricted on the peer side.
|
# restricted on the peer side.
|
||||||
#
|
#
|
||||||
# PLUTO_XAUTH_USER
|
# PLUTO_XAUTH_ID
|
||||||
# is an optional user ID employed by the XAUTH protocol
|
# is an optional user ID employed by the XAUTH protocol
|
||||||
#
|
#
|
||||||
|
|
||||||
|
|||||||
@@ -115,7 +115,7 @@
|
|||||||
# is the UDP/TCP port to which the IPsec SA is
|
# is the UDP/TCP port to which the IPsec SA is
|
||||||
# restricted on the peer side.
|
# restricted on the peer side.
|
||||||
#
|
#
|
||||||
# PLUTO_XAUTH_USER
|
# PLUTO_XAUTH_ID
|
||||||
# is an optional user ID employed by the XAUTH protocol
|
# is an optional user ID employed by the XAUTH protocol
|
||||||
|
|
||||||
# logging of VPN connections
|
# logging of VPN connections
|
||||||
|
|||||||
+9
-8
@@ -464,11 +464,11 @@ static bool do_command(connection_t *c, struct spd_route *sr,
|
|||||||
peerclientnet_str[ADDRTOT_BUF],
|
peerclientnet_str[ADDRTOT_BUF],
|
||||||
peerclientmask_str[ADDRTOT_BUF],
|
peerclientmask_str[ADDRTOT_BUF],
|
||||||
peerca_str[BUF_LEN],
|
peerca_str[BUF_LEN],
|
||||||
xauth_user_str[BUF_LEN] = "",
|
xauth_id_str[BUF_LEN] = "",
|
||||||
secure_myid_str[BUF_LEN] = "",
|
secure_myid_str[BUF_LEN] = "",
|
||||||
secure_peerid_str[BUF_LEN] = "",
|
secure_peerid_str[BUF_LEN] = "",
|
||||||
secure_peerca_str[BUF_LEN] = "",
|
secure_peerca_str[BUF_LEN] = "",
|
||||||
secure_xauth_user_str[BUF_LEN] = "";
|
secure_xauth_id_str[BUF_LEN] = "";
|
||||||
ip_address ta;
|
ip_address ta;
|
||||||
pubkey_list_t *p;
|
pubkey_list_t *p;
|
||||||
|
|
||||||
@@ -508,10 +508,11 @@ static bool do_command(connection_t *c, struct spd_route *sr,
|
|||||||
if (c->xauth_identity &&
|
if (c->xauth_identity &&
|
||||||
c->xauth_identity->get_type(c->xauth_identity) != ID_ANY)
|
c->xauth_identity->get_type(c->xauth_identity) != ID_ANY)
|
||||||
{
|
{
|
||||||
snprintf(xauth_user_str, sizeof(xauth_user_str),
|
snprintf(xauth_id_str, sizeof(xauth_id_str), "%Y", c->xauth_identity);
|
||||||
"PLUTO_XAUTH_USER='%Y' ", c->xauth_identity);
|
escape_metachar(xauth_id_str, secure_xauth_id_str,
|
||||||
escape_metachar(xauth_user_str, secure_xauth_user_str,
|
sizeof(secure_xauth_id_str));
|
||||||
sizeof(secure_xauth_user_str));
|
snprintf(xauth_id_str, sizeof(xauth_id_str), "PLUTO_XAUTH_ID='%s' ",
|
||||||
|
secure_xauth_id_str);
|
||||||
}
|
}
|
||||||
|
|
||||||
addrtot(&sr->that.host_addr, 0, peer_str, sizeof(peer_str));
|
addrtot(&sr->that.host_addr, 0, peer_str, sizeof(peer_str));
|
||||||
@@ -571,7 +572,7 @@ static bool do_command(connection_t *c, struct spd_route *sr,
|
|||||||
"PLUTO_PEER_PROTOCOL='%u' "
|
"PLUTO_PEER_PROTOCOL='%u' "
|
||||||
"PLUTO_PEER_CA='%s' "
|
"PLUTO_PEER_CA='%s' "
|
||||||
"%s" /* optional PLUTO_MY_SRCIP */
|
"%s" /* optional PLUTO_MY_SRCIP */
|
||||||
"%s" /* optional PLUTO_XAUTH_USER */
|
"%s" /* optional PLUTO_XAUTH_USER_ID */
|
||||||
"%s" /* actual script */
|
"%s" /* actual script */
|
||||||
, verb, verb_suffix
|
, verb, verb_suffix
|
||||||
, c->name
|
, c->name
|
||||||
@@ -595,7 +596,7 @@ static bool do_command(connection_t *c, struct spd_route *sr,
|
|||||||
, sr->that.protocol
|
, sr->that.protocol
|
||||||
, secure_peerca_str
|
, secure_peerca_str
|
||||||
, srcip_str
|
, srcip_str
|
||||||
, secure_xauth_user_str
|
, xauth_id_str
|
||||||
, sr->this.updown == NULL? DEFAULT_UPDOWN : sr->this.updown))
|
, sr->this.updown == NULL? DEFAULT_UPDOWN : sr->this.updown))
|
||||||
{
|
{
|
||||||
loglog(RC_LOG_SERIOUS, "%s%s command too long!", verb, verb_suffix);
|
loglog(RC_LOG_SERIOUS, "%s%s command too long!", verb, verb_suffix);
|
||||||
|
|||||||
Reference in New Issue
Block a user